IP Library › Patent Application 18400626
Patent Application
App. No. 18/400,626

TECHNIQUES FOR CYBERSECURITY IDENTITY RISK DETECTION UTILIZING DISK CLONING AND UNIFIED IDENTITY MAPPING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/400,626
Abstract

A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.

Claims (73)

1 . A method for detecting a permission escalation event in a computing environment, comprising:

generating a cloned disk based on an original disk of a resource deployed in a computing environment;

detecting an identifier of a first principal on the cloned disk;

detecting a second principal in the computing environment, wherein the first principal is authorized to assume the first principal;

storing a representation of the computing environment in a security database, the representation including: a first principal node representing the first principal, and a second principal node representing the second principal, the second principal node further associated with a permission;

querying the representation to determine a permission of the first principal;

determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and

generating a permission escalation event in response to determining that the second principal includes a permission which the first principal does not include.

2 . The method of claim 1 , further comprising:

determining that a permission associated with the first principal node is granted by the second principal; and

determining that the permission escalation event is triggered by granting the permission.

3 . The method of claim 1 , further comprising:

querying the security database to detect a third principal node representing a third principal deployed in a second computing environment, wherein the third principal includes a permission to assume the first principal.

4 . The method of claim 1 , further comprising:

determining an effective permission of the first principal.

5 . The method of claim 4 , wherein determining an effective permission further comprises:

determining a plurality of secondary principals, wherein the first principal is configured to assume each secondary principal; and

determining a permission for each secondary principal.

6 . The method of claim 5 , wherein the effective permission includes each determined permission.

7 . The method of claim 4 , further comprising:

detecting a group of principals including the first principal in the security database, wherein the security database is a security graph stored on a graph database.

8 . The method of claim 7 , wherein detecting the group of principals further comprises:

applying maximal biclique detection on the security graph.

9 . The method of claim 7 , further comprising:

determining an effective permission for the group of principals by determining an effective permission of the first principal.

10 . The method of claim 1 , further comprising:

releasing the cloned disk in response to completing inspection of the cloned disk.

11 . The method of claim 1 , further comprising:

inspecting the cloned disk for a cybersecurity object.

12 . The method of claim 11 , further comprising:

storing a representation of the cybersecurity object in the security database, in response to detecting the cybersecurity object in the cloned disk.

13 . A non-transitory computer-readable medium storing a set of instructions for detecting a permission escalation event in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

generate a cloned disk based on an original disk of a resource deployed in a computing environment;

detect an identifier of a first principal on the cloned disk;

detect a second principal in the computing environment, wherein the first principal is authorized to assume the first principal;

store a representation of the computing environment in a security database, the representation including: a first principal node represent the first principal, and a second principal node representing the second principal, the second principal node further associated with a permission;

query the representation to determine a permission of the first principal;

determine that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and

generate a permission escalation event in response to determining that the second principal includes a permission which the first principal does not include.

14 . A system for detecting a permission escalation event in a computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a cloned disk based on an original disk of a resource deployed in a computing environment;

detect an identifier of a first principal on the cloned disk;

detect a second principal in the computing environment, wherein the first principal is authorized to assume the first principal;

store a representation of the computing environment in a security database, the representation including: a first principal node represent the first principal, and a second principal node representing the second principal, the second principal node further associated with a permission;

query the representation to determine a permission of the first principal

determine that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and

generate a permission escalation event in response to determining that the second principal includes a permission which the first principal does not include.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that a permission associated with the first principal node is granted by the second principal; and

determine that the permission escalation event is triggered by granting the permission.

16 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

query the security database to detect a third principal node representing a third principal deployed in a second computing environment, wherein the third principal includes a permission to assume the first principal.

17 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine an effective permission of the first principal.

18 . The system of claim 17 , wherein the memory contains further instructions that, when executed by the processing circuitry for determining an effective permission, further configure the system to:

determine a plurality of secondary principals, wherein the first principal is configured to assume each secondary principal; and

determine a permission for each secondary principal.

19 . The system of claim 18 , wherein the effective permission includes each determined permission.

20 . The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a group of principals including the first principal in the security database, wherein the security database is a security graph stored on a graph database.

21 . The system of claim 20 , wherein the memory contains further instructions that, when executed by the processing circuitry for detecting the group of principals, further configure the system to:

apply maximal biclique detection on the security graph.

22 . The system of claim 20 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine an effective permission for the group of principals by determining an effective permission of the first principal.

23 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

release the cloned disk in response to completing inspection of the cloned disk.

24 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect the cloned disk for a cybersecurity object.

25 . The system of claim 24 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

store a representation of the cybersecurity object in the security database, in response to detecting the cybersecurity object in the cloned disk.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2024
From: SHEMESH, DANIEL HERSHKO; MIRAN, YARIN; REZNIK, ROY; LUTTWAK, AMI; COSTICA, YINON; BERKOVITZ, AVIHAI; PISHA, GEORGE; OLIVER, YANIV JOSEPH; REITBLAT, UDI; HELLER, OR; HERZBERG, RAAZ; HAZAN, OSHER; BEN DAVID, NIV ROIT
To: WIZ, INC.
Reel/Frame 066326/0027 →